top of page
Coffee and croissants at Castle Heights Self Catering in front of spectacular Edinburgh Castle.

Privacy & Cookies

Last updated: 15 June 2020

 

Data protection

Castle Heights is committed to keeping your data safe and secure and handling it appropriately within the guidelines of the General Data Protection Regulation ("GDPR"). This Privacy Policy ("Policy") explains how we may collect personal data about you, and how you can exercise your privacy rights. It also outlines the security measures we take in order to protect your privacy and gives assurances on things that we will not do.

If you have any questions or concerns about our use of your personal data, then please contact us using the contact details provided at the bottom of this Policy.

What does Castle Heights do?

Castle Heights is a unique holiday apartment in Edinburgh that can be booked for short holiday lets.

What personal data does Castle Heights collect and why?

The personal data that we may collect about you broadly falls into the following categories:

Personal data that you provide voluntarily

Certain parts of our website may ask you to provide personal data voluntarily: for example, we may ask you to provide your contact details in order to subscribe to marketing communications from us, and/or to submit enquiries and bookings to us.  We may ask you to provide your credit card information to facilitate booking.

Personal data that we collect automatically

When you visit our website, we may collect certain information automatically from your device.  In some countries, including countries in the European Economic Area, this information may be considered personal data under applicable data protection laws.

Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, broad geographic location (e.g. country or city-level location) and other technical information, for example, data we collect for fraud prevention.  We may also collect information about how your device has interacted with our website, including the pages accessed and links clicked.  

Collecting this information enables us to better understand the visitors who come to our website, where they come from, and what content on our website is of interest to them.  We use this information for our internal analytics purposes and to improve the quality and relevance of our website to our visitors.

Cookies

We may use cookies for a number of reasons to improve your experience on our website. Cookies are small pieces of information that are stored on your device by your browser. These allow us to store your account information and provide features to make browsing and booking easier. Most browsers allow the cookie function to be turned off. If you want to know how to do this, please look at the help menu on your browser.

Use of your personal data

We will use personal data for a number of purposes, including:

Servicing your bookings

Completing travel bookings (this includes sharing your booking information with other parties to fulfil your booking).

advising you of any changes to or problems with a booking.

to send you marketing communications.

Your data protection rights

If you are a resident of the European Economic Area, you have the following data protection rights:

If you wish to access, correct or update of your personal data, you can do so at any time by writing to us using the contact details provided at the bottom of this Policy or under 'contact us' . 

You can delete your personal data by contacting us in writing by email or through the Contact Us form to request its removal.

If you have signed up to receive marketing communications from us you have the right to opt-out of marketing communications we send you at any time.  You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you.

Similarly, if we have collected and processed your personal data with your consent, then you can withdraw your consent at any time.  Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent.

You have the right to complain to a data protection authority about our collection and use of your personal data.  For more information, please contact your local data protection authority. 

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws.

Disclosure of personal data

We may disclose your personal information to the following categories of recipients:

to third party services providers and partners who provide data processing services to us (for example, to support the delivery of, provide functionality on, or help to enhance the security of our website or processing payments, or who otherwise process personal information for purposes that are described in this Policy or notified to you when we collect your personal data. 

to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person.

Legal basis for processing personal data (EEA visitors only)

Our legal basis for collecting and using the personal data described above will depend on the personal data concerned and the specific context in which we collect it. 

However, we will normally collect personal data from you only (i) where we need the personal data to perform a contract with you, (ii) where the processing is in our legitimate interests and not overridden by your rights, or (iii) where we have your consent to do so.  In some cases, we may also have a legal obligation to collect personal data from you or may otherwise need the personal data to protect your vital interests or those of another person.

If we ask you to provide personal data to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal data is mandatory or not (as well as of the possible consequences if you do not provide your personal data).  

If we collect and use your personal data in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.

If you have questions about or need further information concerning the legal basis on which we collect and use your personal information, please contact us using the contact details provided below.

Protection of your personal data

We maintain appropriate technical and organisational measures in order to protect personal data. The measures we use are designed to provide a level of security appropriate to the risk of processing your personal data and includes following certain procedures in order to ensure compliance with the GDPR: the use of encryption, password compliance, firewall and penetration testing, breach handling, employee training and security, and much more.

Data retention

We retain personal data we collect from you where we have an ongoing legitimate business need to do so (for example, to provide you with a service you have requested).  

When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymise it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible. 

Third-party sites

This website may contain links to other websites. Such links are provided solely for your convenience. Castle Heights is not responsible for the security practices of such websites.

We may amend this Policy from time to time, in which case the amended version will be published on our website. This Policy applies to personal information held about individuals. You can see when this Policy was last updated by checking the “last updated” date.

Contact us

If you’d like to contact us please use the Contact Us form or email us at:

hello@castleheights.co.uk

bottom of page